Known vulnerabilities in libssh

Vendor: libssh
Software: libssh
Software CPE: cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
Total vulnerabilities: 46
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libssh libssh is affected by 46 known vulnerabilities: 3 high, 22 medium, 21 low Critical High Medium Low

Vulnerabilities (46)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139533 - Use After Free
CVE-2026-59850
CWE-416 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 7 more
#VU139532 - Always-Incorrect Control Flow Implementation
CVE-2026-59849
CWE-670 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260817115
#VU139531 - Resource exhaustion
CVE-2026-59848
CWE-400 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 1 more
#VU139530 - Improper Validation of Integrity Check Value
CVE-2026-59847
CWE-354 Medium
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 7 more
#VU139529 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-59846
CWE-78 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 1 more
#VU139528 - Out-of-bounds read
CVE-2026-59842
CWE-125 Low
No
No
0.12.1 27.07.2026 SB20260727145
SB20260817115
#VU139527 - Improper input validation
CVE-2026-59844
CWE-20 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 6 more
#VU139526 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-59843
CWE-835 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 6 more
#VU139525 - Stack-based buffer overflow
CVE-2026-15370
CWE-121 Medium
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260817115
#VU139524 - Improper Check or Handling of Exceptional Conditions
CVE-2026-59845
CWE-703 Low
No
No
0.11.5, 0.12.1 27.07.2026 SB20260727145
SB20260728129
SB20260728153
and 7 more
#VU139523 - Improper Access Control
CVE-2026-59851
CWE-284 Medium
No
No
0.12.1 27.07.2026 SB20260727145
SB20260817115
#VU139522 - Improper Access Control
CVE-2025-14821
CWE-284 Low
No
No
0.11.4, 0.12.0 27.07.2026 SB2026022406
#VU123156 - Out-of-bounds read
CVE-2026-0968
CWE-125 Medium
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123155 - Improper input validation
CVE-2026-0967
CWE-20 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123154 - Buffer Underwrite ('Buffer Underflow')
CVE-2026-0966
CWE-124 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123153 - Improper input validation
CVE-2026-0965
CWE-20 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 9 more
#VU123151 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-0964
CWE-22 Medium
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU115175 - Missing release of memory after effective lifetime
CVE-2025-8277
CWE-401 Medium
No
No
0.11.3 12.09.2025 SB2025091210
SB2025091219
SB2025091220
and 11 more
#VU115174 - Integer overflow
CVE-2025-5449
CWE-190 Medium
No
No
0.11.2 12.09.2025 SB2025091209
SB2025091215
SB2025091577
#VU115173 - NULL Pointer Dereference
CVE-2025-8114
CWE-476 Medium
No
No
0.11.3 12.09.2025 SB2025091208
SB2025091219
SB2025091220
and 12 more


Showing elements 1 - 20 out of 46